<div dir="ltr">Actually, and never mind on how that cert is used.  If my curiosity gets the better of me I'll read more on PKIX.</div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><span style="font-size:12.8px">--Tom Noonan II</span><br></div></div></div></div></div></div>
<br><div class="gmail_quote">On Wed, Feb 28, 2018 at 4:18 PM, Tom Noonan <span dir="ltr"><<a href="mailto:tom@joinroot.com" target="_blank">tom@joinroot.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Thanks.  So making sure I'm understanding things right:<div><br></div><div>- If no TrustEngine is specified the ExplicitKey engine is tried, and then the PKIX engine (<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPTrustEngine" target="_blank">https://wiki.shibboleth.net/c<wbr>onfluence/display/SHIB2/Native<wbr>SPTrustEngine</a>)</div><div>- The CredentialResolver config is used by the StaticPKIX engine.</div><div><br></div><div>I'm still not clear on how the CredentialResolver certificate is used.  This is just academic for me at this point, though, as after reading these docs I verified that the ExplicitKey is the trust engine I should use, so I've removed the cert in question from my config.</div><div class="gmail_extra"><br clear="all"><div><div class="m_-5147436836386620253m_-115801187754402842gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><span style="font-size:12.8px">--Tom Noonan II</span><br></div></div></div></div></div></div>
<br><div class="gmail_quote">On Tue, Feb 27, 2018 at 12:17 PM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Tom Noonan <<a href="mailto:tom@joinroot.com" target="_blank">tom@joinroot.com</a>> [2018-02-27 17:14]:<br>
> I'm currently using a self-signed certificate for the SP Credential<br>
> resolver, by config for this is same as the example:<br>
><br>
> <CredentialResolver type="File" key="/etc/shibboleth/sp.key"<br>
> certificate="/etc/shibboleth/s<wbr>p.crt"/><br>
><br>
> This works fine, I have no login errors.  However, I'm not clear on how<br>
> this certificate is used.  Am I opening myself up to spoofing attacks by<br>
> using a self-signed certificate for this?<br>
<br>
See<br>
<a href="https://wiki.shibboleth.net/confluence/display/CONCEPT/TrustManagement" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/co<wbr>nfluence/display/CONCEPT/Trust<wbr>Management</a><br>
esp. "Inline / Explicit Key Trust Engine"<br>
<br>
The formal write-up of this can be found here:<br>
<a href="https://wiki.oasis-open.org/security/SAML2MetadataIOP" rel="noreferrer" target="_blank">https://wiki.oasis-open.org/se<wbr>curity/SAML2MetadataIOP</a><br>
<span class="m_-5147436836386620253m_-115801187754402842HOEnZb"><font color="#888888"><br>
-peter<span class="HOEnZb"><font color="#888888"><br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/co<wbr>nfluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.n<wbr>et</a><br>
</font></span></font></span></blockquote></div><br></div></div>
</blockquote></div><br></div>